Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-17517

Опубликовано: 27 апр. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and keys thereby exposing data to anonymous clients or users. This affected Apache Ozone prior to the 1.1.0 release.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:ozone:*:*:*:*:*:*:*:*
Версия до 1.1.0 (исключая)

EPSS

Процентиль: 61%
0.00416
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-285
CWE-306

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and keys thereby exposing data to anonymous clients or users. This affected Apache Ozone prior to the 1.1.0 release. Improper Authorization vulnerability in __COMPONENT__ of Apache Ozone allows an attacker to __IMPACT__. This issue affects Apache Ozone Apache Ozone version 1.0.0 and prior versions.

EPSS

Процентиль: 61%
0.00416
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-285
CWE-306